Awesome Logo Carousel Block Security & Risk Analysis

wordpress.org/plugins/awesome-logo-carousel-block

Awesome Logo Carousel Block allows you to create interactive client logos carousel with Gutenberg Block Editor.

5K active installs v2.2.3 PHP 7.4+ WP 6.0+ Updated Mar 31, 2026
carousel-blockimage-carousellogo-carousellogo-sliderslider-block
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 14, 2025
Safety Verdict

Is Awesome Logo Carousel Block Safe to Use in 2026?

Generally Safe

Score 99/100

Awesome Logo Carousel Block has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 14, 2025Updated 1mo ago
Risk Assessment

The static analysis of awesome-logo-carousel-block v2.2.3 reveals a generally strong security posture. The plugin boasts zero identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. Furthermore, the code demonstrates excellent practices by avoiding dangerous functions, performing 100% of its SQL queries using prepared statements, and ensuring all output is properly escaped. File operations and external HTTP requests are also absent, reducing potential attack vectors. The lack of taint analysis findings and the absence of bundled libraries further contribute to a positive assessment.

However, the vulnerability history presents a significant concern. While there are currently no unpatched CVEs, the plugin has a history of one known CVE, specifically a medium-severity Cross-Site Scripting (XSS) vulnerability, which was last patched on April 14, 2025. The presence of a past XSS vulnerability, even if patched, suggests a potential for similar issues to arise if input sanitization or output escaping practices were to be relaxed in future versions. The fact that there are zero nonces checks and zero capability checks is also a notable weakness, especially if the plugin were to introduce any new user-facing features or AJAX/REST endpoints in the future, as these are fundamental security mechanisms for WordPress.

In conclusion, the current version of the plugin exhibits strong secure coding practices in its static analysis. The absence of direct attack surfaces and robust data handling are commendable. Nevertheless, the historical presence of an XSS vulnerability, despite being patched, and the complete absence of nonce and capability checks represent potential areas of future risk and should be monitored. The plugin's overall security is good, but not perfect, due to these historical and procedural considerations.

Key Concerns

  • Past CVE identified (XSS)
  • No nonce checks
  • No capability checks
Vulnerabilities
1 published

Awesome Logo Carousel Block Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-2083medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Logo Carousel Gutenberg Block <= 2.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via sliderId Parameter

Apr 14, 2025 Patched in 2.1.7 (1d)
Version History

Awesome Logo Carousel Block Release Timeline

v2.2.3Current
v2.2.2
v2.2.1
v2.2.0
v2.1.10
v2.1.9
v2.1.8
v2.1.7
v2.1.61 CVE
v2.1.51 CVE
v2.1.41 CVE
v2.1.31 CVE
v2.1.21 CVE
v2.1.11 CVE
v2.1.01 CVE
v2.0.71 CVE
v2.0.61 CVE
v2.0.51 CVE
v2.0.41 CVE
v2.0.01 CVE
Code Analysis
Analyzed Apr 16, 2026

Awesome Logo Carousel Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
54 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped54 total outputs
Attack Surface

Awesome Logo Carousel Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadmin_menuadmin/admin.php:32
actionadmin_enqueue_scriptsadmin/admin.php:33
actionenqueue_block_editor_assetsinc/classes/enqueue.php:39
actionenqueue_block_assetsinc/classes/enqueue.php:40
actioninitinc/classes/register.php:30
filtershould_load_separate_core_block_assetsinc/classes/register.php:32
filterrender_blockinc/classes/style.php:30
filterrender_block_lcb/logo-carouselinc/classes/style.php:31
filterblock_categories_allinc/init.php:39
filterattachment_fields_to_editplugin.php:97
filterattachment_fields_to_saveplugin.php:98
actionrest_api_initplugin.php:99
actionadmin_initplugin.php:102
Maintenance & Trust

Awesome Logo Carousel Block Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 31, 2026
PHP min version7.4
Downloads56K

Community Trust

Rating80/100
Number of ratings4
Active installs5K
Developer Profile

Awesome Logo Carousel Block Developer Profile

Binsaifullah

5 plugins · 27K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect Awesome Logo Carousel Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/awesome-logo-carousel-block/admin/css/admin.css/wp-content/plugins/awesome-logo-carousel-block/admin/js/admin.js
Script Paths
js/admin.js
Version Parameters
awesome-logo-carousel-block/admin/css/admin.css?ver=awesome-logo-carousel-block/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
lc-dashboard-containerlc-dashboard-headerlc-header-leftlc-logoinner-wrapper
Data Attributes
data-alcb-custom-link
JS Globals
alcb_editor_data
REST Endpoints
/wp-json/wp/v2/media-attachment/alcb_custom_link
FAQ

Frequently Asked Questions about Awesome Logo Carousel Block